7.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
16 packages
- fedora-backgrounds.f32
- fedora-backgrounds.f33
- fedora-backgrounds.f34
- fedora-backgrounds.f35
- fedora-backgrounds.f36
- fedora-backgrounds.f37
- fedora-backgrounds.f38
- haskellPackages.fedora-krb
- haskellPackages.fedora-dists
- haskellPackages.fedora-releases
- python313Packages.python-fedora
- python314Packages.python-fedora
- python313Packages.fedora-messaging
- python314Packages.fedora-messaging
- haskellPackages.fedora-haskell-tools
- gnomeExtensions.fedora-linux-update-indicator
- @LeSuisse accepted
- @LeSuisse published on GitHub
NetworkManager-l2tp: local privilege escalation via ipsec.conf injection
A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security association is established, resulting in local privilege escalation. This is the same bug class as CVE-2018-10900 (NetworkManager-vpnc).
References
-
https://github.com/nm-l2tp/NetworkManager-l2tp/releases release-notes
-
https://linnemanlabs.com/posts/nm-l2tp-newline-to-root/ third-party-advisory
Affected products
- <1.20.24
- <1.8.10
- <1.2.22
- <1.0.16
- <1.52.4
Matching in nixpkgs
Ignored packages (16)
pkgs.fedora-backgrounds.f32
Set of default and supplemental wallpapers for Fedora
pkgs.fedora-backgrounds.f33
Set of default and supplemental wallpapers for Fedora
pkgs.fedora-backgrounds.f34
Set of default and supplemental wallpapers for Fedora
pkgs.fedora-backgrounds.f35
Set of default and supplemental wallpapers for Fedora
pkgs.fedora-backgrounds.f36
Set of default and supplemental wallpapers for Fedora
pkgs.fedora-backgrounds.f37
Set of default and supplemental wallpapers for Fedora
pkgs.fedora-backgrounds.f38
Set of default and supplemental wallpapers for Fedora
pkgs.haskellPackages.fedora-krb
Kerberos for Fedora packagers
pkgs.haskellPackages.fedora-dists
Library for Fedora distribution versions
pkgs.haskellPackages.fedora-releases
Library for Fedora release versions
pkgs.python313Packages.python-fedora
Module to interact with the infrastructure of the Fedora Project
pkgs.python314Packages.python-fedora
Module to interact with the infrastructure of the Fedora Project
pkgs.python313Packages.fedora-messaging
Library for sending AMQP messages with JSON schema in Fedora infrastructure
pkgs.python314Packages.fedora-messaging
Library for sending AMQP messages with JSON schema in Fedora infrastructure
pkgs.haskellPackages.fedora-haskell-tools
Building and maintenance tools for Fedora Haskell
Package maintainers
-
@obadz obadz <obadz-nixos@obadz.com>